ISO 27001 clause 9.2
ISO 27001 requires internal audits at planned intervals, conducted so that objectivity and impartiality are assured. In a small team that is the hard part - which is why this is the one piece of the management system most companies bring in from outside.
What the standard asks for
Clause 9.2 is short, and every part of it is checked by your certification body at the next surveillance visit. These are the five things it asks of you.
Not a one-off. The organisation runs internal audits on a programme, so that the whole management system is covered over time rather than the same easy corner being re-audited every year.
Frequency, methods, responsibilities, planning requirements and reporting - defined and maintained, not improvised the month before the certification body arrives.
Auditors are selected, and audits conducted, so that the process is objective and impartial. This is the requirement most internal audits quietly fail.
The findings go to the management that can act on them, and they become an input to the management review under clause 9.3.
The audit programme and its results are kept as documented information. An audit nobody can evidence did not happen, as far as a certification body is concerned.
Described rather than quoted: ISO/IEC 27001 is a purchasable standard, and the authoritative wording is in your own copy of it.
Independence
Objectivity and impartiality are requirements of the audit process itself. A firm that builds your management system and then audits it has removed the one thing the audit was for.
Straightforward: we did not design your controls, write your policies or choose your Statement of Applicability, so there is nothing for us to be protective of. That is the cleanest version of this engagement, and it is the one most of our internal audit clients are.
Then the audit is run by someone who did not do that work, and the report states the separation explicitly - so your certification body can see how impartiality was preserved rather than take our word for it. Where the separation cannot be made honestly, we say so and you use another auditor. That is a better outcome than a report your external auditor discounts.
We are an independent advisory practice, not a certification body. An internal audit from us is your clause 9.2 audit - it is not certification, and it does not guarantee any external audit outcome.
What you get
Typically 3-5 days of audit effort. You know what is being examined, who we need, and exactly what lands at the end.
Agreed before anything starts: scope, audit criteria, how we will sample, who we need and when. You know exactly what is being examined.
Clauses 4-10 and the Annex A controls in your Statement of Applicability. Interviews with control owners, and sampling of the evidence as it actually exists - not as the policy says it should.
Each finding recorded as a nonconformity, an observation or an opportunity for improvement, with the clause or control it sits against and the evidence behind it.
Written in the form a certification body expects to receive, so it stands up when your external auditor asks to see last year's internal audit.
The findings shaped as an input to clause 9.3, so the review has something to review rather than a verbal summary.
A walkthrough with the people who have to act on the findings, so the report does not go straight into a folder.
Scoped on a call
Your clause 9.2 internal audit, run by an auditor with no stake in the system being audited - with the report your management review actually needs.
What changes the price: Number of controls in your Statement of Applicability · Number of legal entities and sites in scope · How many control owners have to be interviewed · Whether the last audit left open nonconformities to verify
Independent by design: we do not audit an ISMS we built. Where we have done remediation for you, the audit is run by someone who did not do that work, and we say so in the report.
Questions
No, and they are not interchangeable. The internal audit is yours: the standard requires you to run it, and you own the findings. The certification body's Stage 1, Stage 2 and surveillance audits are external and end in a certificate. One of the things the external auditor checks is that your internal audit actually happened and was done properly.
They can, and many organisations do - but the standard requires the audit to be conducted so that objectivity and impartiality are assured, and that is the hard part in a small team. Someone cannot audit their own work, and in a company where three people run everything there is often nobody left who is genuinely independent of the area being audited. That is the usual reason this gets outsourced.
Not the parts we built. Independence is a requirement of the audit, not a preference of ours, so where we have done readiness or remediation work for you the internal audit is run by someone who did not do that work - and the report says so, so your certification body can see the separation rather than take our word for it.
Typically 3-5 days of audit effort, depending on how many controls are in your Statement of Applicability, how many entities and sites are in scope, and how many control owners have to be interviewed. The elapsed calendar time depends mostly on how quickly interviews can be scheduled.
That is the audit working. A finding raised by your own internal audit, with a corrective action underway, is a healthy management system - it is far better than the same issue being found by the certification body, where it becomes a finding on your certificate rather than a line in your own improvement log.
The scope, the deliverables and the factors that move the price are all published - the figure is agreed on a short call, because it depends on the size of your Statement of Applicability and how many entities are in scope. Nothing starts before the scope and the fixed price are agreed in writing.
Tell us the size of your Statement of Applicability and when your next surveillance visit is. We will confirm the scope and a fixed price in writing before anything starts.